Information Retention Policy for Wanted Dead Or a Wild Slot Game in the United Kingdom

Playing Wanted Dead Or a Wild Slot means handing over personal data wanteddeadorwild.uk. This document lays out exactly how long we store it, the reasons, and what technical protections sit behind each category—all built around UK GDPR, the Data Protection Act 2018, and PCI DSS. We manage identity documents, financial transactions, gameplay telemetry, responsible gambling markers, and marketing consents, each with its own retention clock. Identity records are kept for five years after account closure. Financial logs remain for seven, meeting HMRC requirements. Gameplay data undergoes 24 months before anonymisation takes effect. Full card numbers never touch our systems—only tokenised aliases—and every byte is secured. Independent auditors verify our automated deletion routines, and any schedule slip activates a full incident response. A version-controlled policy log documents every edit, and we give you 30 days’ notice before material changes take effect. Subject access and deletion requests are processed within statutory deadlines.

Fundamental Definitions and Extent of Personal Data

We take a broad view on what qualifies as personal data. Direct identifiers—name, email, billing address, masked payment details—sit alongside indirect signals like hashed IP addresses, device fingerprints, browser agents, and advertising tokens. Behavioural data includes session length, bet sizing, spin velocity, and how often feature triggers fire. Even pseudonymised logs can re-identify a person when stitched together, so we handle them as personal. Our lawful bases are contractual necessity, legitimate interest for fraud prevention, and explicit consent for game-related marketing. Full card numbers get tokenised before storage. We never collect special category data. Encryption and access controls apply uniformly, and retention rules span live databases, archives, and backups without exception. Each window begins counting from the last activity or transaction date, spelled out below. We revisit definitions every six months to remain compliant with regulatory guidance.

Gameplay Session and Analytics of Behavior Data

Each spin on Wanted Dead Or a Wild tracks reel positions, RNG seed, and net outcome with microsecond precision. We keep these raw logs for twenty-four months, then compress them into an anonymous statistical digest utilized for game design. Session behavioural profiles—average bet, spin cadence, feature buy-ins—stay for the same 24-month window and are then deleted. Feature trigger heatmaps stay for 12 months before merging into a global model. RNG seed audit trails receive 36 months. Error diagnostics receive 90 days. No individual gameplay data goes into credit or marketing profiling. All logs are encrypted and off-limits to marketing teams.

  • Spin-level logs: 24 months from event date, then anonymised aggregation
  • Session behavioural profiles: 24 months from last session, then deleted
  • RNG seed audit trails: 36 months to comply with technical standards
  • Feature trigger heatmaps: 12 months, then merged into global model
  • Error and crash diagnostic logs: 90 days, then rotated out

Marketing Consent and Communication Logs

We store your consent document—timestamped, IP-stamped, and method-recorded—for the life of our association plus six years after cancellation, to comply with PECR obligations. Dispatch records for electronic messages, push messages, and SMS are kept for only thirteen months. Cancelling consent right away halts communications while keeping historical proof. A partitioned database provides suppression without delay, and consent logs are stored in a distinct compliance archive. Delivery logs hold metadata only—topic, time, state—not full message body. The six-year post-withdrawal timeframe matches the statute of limitations for regulatory probes. Quarterly audits verify no expired consents initiate mailings. We never tailor offers with gameplay or financial data beyond explicit authorisations.

Responsible Gambling and Player Ban Registers

Deposit limits, time checks, and timeout settings are kept for your account’s entire duration and never removed while it is active. If you choose to ban yourself, your hashed identity and device fingerprints are added to a specific exclusion register maintained permanently under UKGC licence requirements. The register is secured separately, queried only at login or registration, and never utilized for analytics. Entry is confined to educated compliance staff, and all searches are tracked for three years. The register stores only identity blocks—no banking or gameplay records. We check it annually to correct errors and remove deceased individuals. Apart from that, it is kept everlasting. This retention is mandatory and excluded from deletion requests.

Time Check and Gaming Duration Enforcement

Reality check timers use transient session counters that reset every 24 hours, restarting from your first spin after midnight. Your chosen interval—say, 30 minutes—is stored persistently and routinely reactivates when you visit again, even after a long break. Altering the interval mid-session introduces the new value right away for the next reminder. These settings are removed only upon verified account deletion. Session timer data sits in a dedicated, encrypted store separate from gameplay analytics. The 24-hour counter is based on play start, not midnight, for precision. All timer configurations are auditable through the same three-year access log standard. We at no time categorize or promote based on these settings.

Financial Transaction and Billing Records

Deposit, withdrawal, and wager histories are maintained for seven years from the transaction date, per HMRC and FCA rules. We never store full PANs or CVVs. We capture only the BIN, last four digits, and a tokenised alias. Chargeback disputes suspend the contested record until final outcome, after which the seven-year clock resumes. Data is partitioned quarterly so automated purging works cleanly, with monthly deletion runs audited by auditors. Tokenised card references stay valid only while your account is live and are wiped within thirty days of closure. Combined, anonymised totals remain for financial reporting without any personal details. All financial data is secured and isolated from marketing systems.

Tokenised Payment Instruments and Processor References

Payment gateways generate vaulted tokens that associate your card to a non-sensitive reference. We hold them for the account lifetime plus a thirty-day grace interval, then transmit deletion commands to the processor and wipe our own reference. The only trace left behind is an anonymised transaction hash used in aggregate statements, themselves removed after seven years. No usable credentials ever sit on our systems. We check token revocation daily and raise incidents if deletion is unsuccessful. Tokens are tied to our merchant code and cannot be used other places. Weekly reconciliation confirms correctness, and tokens tied to lost or stolen cards are invalidated immediately. All token operations are logged and verifiable. Aggregate reports never disclose individual transaction hashes.

User Account and Verification of Identity Data

Main identity data—government ID scans, residence proof, biometric selfie verifications—are retained for 5 years after your last session or closure of account, whichever occurs later. This covers statutory limitation periods and anti-money laundering responsibilities. We retrieve only the essentials: document number, validity, nationality. The original image gets shredded right after extraction. Once 5 years pass, all source data is purged, but a cryptographic hash of the verification data lives on for an additional two years inside an audit log. Identity data sits encrypted in storage with AES-256-GCM, kept separate from analytics, and every access is logged for a three-year period. Unnecessary fields like birthplace are deleted at verification stage to shrink the data volume. Annual reviews verify accuracy and proactively delete outdated records.

Uploading Documents and Biometric Processing

Submit an ID through our secure portal and automated checking finishes within ninety seconds. We retrieve the document number, expiry, nationality, and a confidence score, then shred the high-resolution image immediately—it is never stored on disk. The source file stays in an temporary memory and is removed after handling. A reduced, stamped preview is produced for compliance purposes and stored only for the identity verification period. That preview lives in a write-once storage with tight controls and is never exposed to client support. Extracted fields are encoded and kept for the 5-year-plus-2-year hash period. All processing runs on ISO 27001 certified UK servers, and every thumbnail access is recorded immutably.

Biometric Information Details

Live detection checks capture a quick video completely in memory. Video frames are analyzed and deleted within a few milliseconds. Only a data vector of face features remains. This data set contains no image data and cannot be turned back into a picture. It is kept for the entire identity verification process and is permanently deleted upon account termination or after 5 years. The vector sits in a dedicated HSM with automatic expiration and is never exported. Login comparisons happen inside the HSM’s safe environment without disclosing the original vector. The vector is bound to a pseudonym disconnected from marketing profiles, which makes re-identifying very hard. Even IT admins cannot view or rebuild face characteristics from the stored vector.

Access Request and Erasure Workflows

When an SAR lands, we generate a structured JSON/CSV export of all non-purged data within one month, prolongable by two months for complex cases. The export includes live databases, encrypted archives, and processor tokens, sent via a one-time secure link that expires in 72 hours. For deletion, we proceed sequentially: immediate account suppression and token revocation, then scheduled erasure of all personal data not subject to legal hold. We generate a confirmation report detailing erased versus retained categories and their justifications. This report is kept as auditable proof for as long as the longest surviving data category. All requests are documented immutably for five years.

Infrastructure Setup and Data Residency

All data sits in UK-based ISO 27001 Tier III+ data centres, never replicated outside the UK. A hot disaster recovery site in a separate UK zone syncs every six hours. Backups are encrypted client-side and follow identical retention rules. We implement least privilege with hardware MFA for administrators, recording their sessions in an immutable three-year audit trail. Multi-factor authentication combines a hardware token and biometric check. Penetration tests run quarterly, and an independent auditor validates automated purge schedules. Any deviation raises a Severity 1 incident, notified to our DPO within four hours. We also operate an air-gapped backup rotated weekly, under the same deletion policies.

Encryption Key Lifecycle Management

Master keys are renewed every 90 days automatically inside an HSM. New keys are never exported in plaintext. Rotated keys are stored for the data’s retention period plus 12 months for lawful forensic access. When a data category is purged, its key is deleted inside the HSM, making any backups unrecoverable. We assign each key to a single data partition, do not reuse, and conduct quarterly witnessed key ceremonies logged immutably for five years. The offline archive of old keys demands dual control and is stored on write-once media in a fireproof safe. Annual recovery drills guarantee forensic decryption works when needed. No plaintext key material ever exits the HSM boundary.

Policy Assessment and Breach Notification Protocols

We assess this policy every six months or upon material change to the game or regulation. Reviews are minuted with DPO, CISO, and legal counsel. A public summary is published in our privacy centre, minus confidential details. Material changes are emailed 30 days ahead. Minor edits are silently recorded. If a breach occurs affecting data under this policy, we notify affected individuals within 72 hours if high risk, submit with the ICO, and publish a transparency notice. Third-party processor breaches must follow the same protocol. We keep a breach notification log audited quarterly. Post-incident reviews adjust controls as needed. Biannual tabletop exercises test misconfigurations and ransomware to test our response.

Policy Version Control and Change Log

We preserve a version-controlled history of this policy with semantic versioning and plain-English summaries of each change. The log specifies exactly which sections changed and why. Previous versions remain accessible for comparison, so you can see precisely what was added or removed. Material modifications affecting your rights are communicated via email at least thirty days in advance. Minor typographical fixes are deployed silently but still recorded. Each entry is cryptographically signed to prove integrity, and annual independent audits verify the log’s accuracy. The log is a living document reflecting our evolving data practices. You can view the full change log through a link in our privacy centre at any time. This transparent approach demonstrates our commitment to accountable data governance.